medium · CVSS v3 5.4 · CVSS v4 5.3
CVE-2026-92778
CMAK versions through 3.0.0.6 fail to enforce the scheduled leader election feature toggle on HTML form routes. This allows users with web i
Overview
CMAK versions through 3.0.0.6 fail to enforce the scheduled leader election feature toggle on HTML form routes. This allows users with web interface access to bypass the feature gate and interact directly with the form endpoints. Consequently, unauthorized actors can start or stop the recurring election scheduler, potentially disrupting leadership across managed Kafka clusters.
Description
CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.
Impact
Impacts Kafka cluster management availability and operational integrity. Confidentiality is unaffected, integrity is slightly impacted by unauthorized management state changes, and availability is moderately impacted due to forced changes in cluster leadership scheduling.
Remediation
Update CMAK to a fixed release beyond version 3.0.0.6 when available. As a workaround, restrict network access to the CMAK management console using firewalls, VPNs, or strict reverse-proxy access controls to ensure only authorized personnel can reach the web interface.
Risk context
Presents a medium severity level (CVSS v3: 5.4, CVSS v4: 5.3) with no EPSS score reported. The vulnerability requires network access to the management console and poses a moderate threat to operational stability rather than data exposure.
Affected products
- CMAK
- Yahoo Kafka Manager
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 5.4
- CVSS v4
- 5.3
- EPSS
- —